CVE-2026-72666: Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72666?
The severity of CVE-2026-72666 is medium, rated at 6.8.
How do I fix CVE-2026-72666?
To fix CVE-2026-72666, ensure you update to the latest version of Kibana where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-72666?
CVE-2026-72666 is an authorization bypass vulnerability that allows unauthorized access through user-controlled keys.
What impact does CVE-2026-72666 have on managed hosts?
CVE-2026-72666 can lead to unauthorized query execution on managed hosts associated with an inaccessible Kibana space.
Which software is affected by CVE-2026-72666?
CVE-2026-72666 affects Elastic Kibana and Elastic Agent.